ESET Security. (2019, November 19). Mispadu: Advertisement for a discounted Unhappy Meal. Retrieved March 13, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareMispadu | Mispadu uses a custom algorithm to obfuscate its internal strings and uses hardcoded keys. Mispadu also uses encoded configuration files and has encoded payloads using Base64. |
| T1041 Exfiltration Over C2 Channel |
MalwareMispadu | Mispadu can sends the collected financial data to the C2 server. |
| T1056.001 Keylogging |
MalwareMispadu | Mispadu can log keystrokes on the victim's machine. |
| T1057 Process Discovery |
MalwareMispadu | Mispadu can enumerate the running processes on a compromised host. |
| T1059.005 Visual Basic |
MalwareMispadu | Mispadu’s dropper uses VBS files to install payloads and perform execution. |
| T1082 System Information Discovery |
MalwareMispadu | Mispadu collects the OS version, computer name, and language ID. |
| T1083 File and Directory Discovery |
MalwareMispadu | Mispadu searches for various filesystem paths to determine what banking applications are installed on the victim’s machine. |
| T1113 Screen Capture |
MalwareMispadu | Mispadu has the ability to capture screenshots on compromised hosts. |
| T1115 Clipboard Data |
MalwareMispadu | Mispadu has the ability to capture and replace Bitcoin wallet data in the clipboard on a compromised host. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMispadu | Mispadu decrypts its encrypted configuration files prior to execution. |
| T1176.001 Browser Extensions |
MalwareMispadu | Mispadu utilizes malicious Google Chrome browser extensions to steal financial data. |
| T1204.002 Malicious File |
MalwareMispadu | Mispadu has relied on users to execute malicious files in order to gain execution on victim machines. |
| T1218.007 Msiexec |
MalwareMispadu | Mispadu has been installed via MSI installer. |
| T1218.011 Rundll32 |
MalwareMispadu | Mispadu uses RunDLL32 for execution via its injector DLL. |
| T1497.001 System Checks |
MalwareMispadu | Mispadu can run checks to verify if it is running within a virtualized environments including Hyper-V, VirtualBox or VMWare and will terminate execution if the computer name is “JOHN-PC.” |
| T1518.001 Security Software Discovery |
MalwareMispadu | Mispadu can list installed security products in the victim’s environment. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMispadu | Mispadu creates a link in the startup folder for persistence. Mispadu adds persistence via the registry key `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`. |
| T1555 Credentials from Password Stores |
MalwareMispadu | Mispadu has obtained credentials from mail clients via NirSoft MailPassView. |
| T1555.003 Credentials from Web Browsers |
MalwareMispadu | Mispadu can steal credentials from Google Chrome. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.